Description
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Complete system compromise via network‑accessible vulnerability requiring high privileges
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the Security component of Oracle Hyperion Financial Management. A high‑privileged attacker with network access over HTTP can exploit it to compromise the application and ultimately gain full control of the system. The CVSS vector shows that a successful exploit would give an attacker the ability to read, modify, or delete all data and to disrupt the availability of the service, resulting in loss of confidentiality, integrity, and availability for all data handled by the application.

Affected Systems

The affected product is Oracle Hyperion Financial Management from Oracle Corporation. The only impacted version reported is 11.2.26.0.000; no other versions are included.

Risk and Exploitability

The CVSS Base Score of 7.2 indicates medium‑high severity, with the EPSS score of less than 1 % showing a low but non‑zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access over HTTP and high privilege credentials; it needs no user interaction. Consequently, the threat is most acute for insiders or attackers who already bypassed other controls, and the low attack complexity makes the vulnerability particularly dangerous once access is obtained.

Generated by OpenCVE AI on September 20, 2026 at 06:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Hyperion Financial Management 11.2.26.0.000, as provided in Oracle's security advisory.
  • Restrict HTTP access to the Hyperion service to trusted administrative networks or VLANs to minimize exposure to potential attackers.
  • Enforce strict authentication and least‑privilege for privileged accounts; require strong, unique passwords and multi‑factor authentication for all administrative users.

Generated by OpenCVE AI on September 20, 2026 at 06:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Vulnerability Allows Full System Compromise in Oracle Hyperion Financial Management

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Vulnerability Enabling Full System Takeover via HTTP with High Privileges
Weaknesses CWE-276
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Oracle Hyperion Financial Management Vulnerability Enabling Full System Takeover via HTTP with High Privileges
Weaknesses CWE-276
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hyperion Financial Management
CPEs cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hyperion Financial Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hyperion Financial Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:16.931Z

Reserved: 2026-09-08T21:49:12.406Z

Link: CVE-2026-87246

cve-icon Vulnrichment

Updated: 2026-09-17T12:55:55.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:13.383

Modified: 2026-09-21T13:02:00.490

Link: CVE-2026-87246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management